cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This dumb password rule is from Telekom/T-Systems MyWorkplace.
Telekom's MyWorkplace is a Single Sign On / login hub for their
Open Telekom Cloud which is basically an Amazon AWS clone. It's
rather new and especially for business customers. Especially
because it is for business customers, there's absolutely no reason
to limit a password to 16 characters. Eve...
https://dumbpasswordrules.com/sites/telekomt-systems-myworkplace/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from SAS Eurobonus.
The best thing about rules, is that you can multiple different ones!
Like SAS that allows you to have a long password at least when signing
up, but you'll be sorry if you want to change your password later on.
https://dumbpasswordrules.com/sites/sas-eurobonus/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from HSA Bank.
- Must be minimum 12 characters
- Must not be one of user's past 5 passwords
- Must contain uppercase and lowercase letters
- Must contain a number
- Must not be the same as user's account number or login/username
But also...
- Cannot be longer than 20 characters
https://dumbpasswordrules.com/sites/hsa-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Singapore Airlines.
`/[0-9]{6}/`
https://dumbpasswordrules.com/sites/singapore-airlines/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
🆕 blog! “Cybersecurity for the paranoid business traveller”
Over the years, I've worked for organisations with various levels of risk tolerance for business travellers. Some have been (rightly) paranoid and others have been (wrongly) placid about the threats their employees face.
The fact is, individuals are often targeted for espionage, blackmail, or other…
👀 Read more: https://shkspr.mobi/blog/2026/06/cybersecurity-for-the-paranoid-business-traveller/
⸻
#CyberSecurity
This dumb password rule is from Getin Bank.
The new password should contain at least 10 and a maximum of 20 characters.
The password must contain at least one upper case letter, one lower case
letter and one number. The password cannot contain non-ASCII Polish alphabet
characters, special characters `&<'"` or spaces.
https://dumbpasswordrules.com/sites/getin-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Ameli.fr (French national health insurance).
This was very painful to find a password that works with this one and that I can actually remember (I ended-up using my bank-account number because everything else failed). It took me maybe one hour and I thought I would become crazy (and yes, the session expires frequently while you are actually...
https://dumbpasswordrules.com/sites/ameli-fr-french-national-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Irodoricomics.
A website to buy english-localized doujins. The password must be between 4 and 20 characters long
https://dumbpasswordrules.com/sites/irodoricomics/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from NetworkRail Open Data Feeds.
Does require special characters but limits password length to 20.
https://dumbpasswordrules.com/sites/networkrail-open-data-feeds/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Replit.
Forces to use minimum 8 characters in the password and it must contain at least one uppercase.
https://dumbpasswordrules.com/sites/replit/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Lenovo.
- **Between 8 and 20 characters, not more.**
- 1 alphabetic letter
- 1 number (0-9)
- **1 symbol ($!#&)**
https://dumbpasswordrules.com/sites/lenovo/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
VPNs can help protect children's security online too. They aren’t just used to avoid content blocks.
Restrictions will deter people from using a core cybersecurity tool and create greater risks.
Privacy is online safety ✊️
Sign the petition to #ProtectVPNs in the UK ➡️ https://action.openrightsgroup.org/tell-government-protect-vpn-use-uk
#vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
The only way to create an ironclad age verification system in the UK is extreme digital authoritarianism.
Restrictions on VPNs are an attack on the open Internet and our ability to be secure online – the antithesis of online safety.
Read our briefing ➡️ https://www.openrightsgroup.org/publications/briefing-vpns-and-the-online-safety-act/
#ProtectVPNs #vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
Aside from restrictions, it's been suggested that sites should detect VPN use and bounce users into age verification.
This would be technically flawed, privacy-invasive and would exclude lawful Internet users because VPN traffic can look identical to ordinary encrypted web traffic.
Read our briefing ➡️ https://www.openrightsgroup.org/publications/briefing-vpns-and-the-online-safety-act/
#ProtectVPNs #vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
Banning or blocking VPNs in the UK will shatter cybersecurity in a self-defeating attempt to make the unworkable workable.
Creating uncertainty around core Internet infrastructure could undermine the UK’s credibility as a stable place for digital businesses and security innovation.
Read our briefing ➡️ https://www.openrightsgroup.org/publications/briefing-vpns-and-the-online-safety-act/
#ProtectVPNs #vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
VPNs aren’t a meaningful threat to age verification measures.
⚫ 6-12 year olds are very unlikely to use them due to technological and economic barriers.
⚫ Older teens already know other workarounds.
Banning or restricting VPNs in the UK is overreach. The price is our privacy and security.
Read our briefing ➡️ https://www.openrightsgroup.org/publications/briefing-vpns-and-the-online-safety-act/
#ProtectVPNs #vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
An adult using a VPN doesn't impact the safety of a child online.
Adults use VPNs because they don’t trust age verification providers with their personal data.
Something the UK government has refused to deal with by regulating the industry to ensure high standards of data protection.
Read more ➡️ https://www.openrightsgroup.org/publications/regulating-age-verification/
#ProtectVPNs #vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
Treating VPNs as a 'problem' is foolish.
They help parents manage online risks, support secure remote working, protect people in abusive situations, and provide a lifeline to people in repressive States.
UK MPs themselves use them!
Attacking VPNs throws the baby out with the bath water.
Read our briefing ➡️ https://www.openrightsgroup.org/publications/briefing-vpns-and-the-online-safety-act/
#ProtectVPNs #vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
The UK government could announce restrictions on VPNs next month.
This would threaten our privacy and security.
VPNs keep young people safe from harassment. Businesses secure. Journalists, activists and whistleblowers protected.
Here's why we must #ProtectVPNs 🧵
Sign the petition if you agree ⬇️
https://action.openrightsgroup.org/tell-government-protect-vpn-use-uk
#vpn #vpns #cybersecurity #privacy #onlinesafety #onlinesafetyact #ageverification #StopKillingTheInternet #ukpolitics #ukpol
Thx to AI Linux will soon stop being a platform for retrocomputing hardware. Old hw support is getting deprecated to reduce the attack surface.
Meanwhile the Linux Foundation is creating its nth AI/crypto related group.
#opensource #linux #ai #cybersecurity #retrocomputing #retrogaming
This dumb password rule is from California Department of Motor Vehicles.
They also prohibit pasting into the password field by using a JavaScript
`alert()` whenever you right-click or press the `Ctrl` button, so
you can't use a password manager.
https://dumbpasswordrules.com/sites/california-department-of-motor-vehicles/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Ancestry.
Password:
- Must be at least 8 characters long
- Must contain at least 1 number
- Must contain at least 1 letter or special character
- Must not be a well known or common password
https://dumbpasswordrules.com/sites/ancestry/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
VPNs help people stay safe and secure online.
If adults use them to by-pass ID checks, it's because they don't trust unregulated age verification providers with their data.
We mustn't bulldoze cybersecurity with another authoritarian attack on the open Internet.
Sign the petition #ProtectVPNs in the UK ⬇️
https://action.openrightsgroup.org/tell-government-protect-vpn-use-uk
#vpn #socialmediaban #ageverification #ukpolitics #cybersecurity #onlinesafety #ukpolitics #ukpol
🚨 First the social media ban, now the UK government wants to restrict VPNs 🚨
VPNs are a vital cybersecurity tool for businesses, politicians, journalists and families to protect data and communications.
Banning or requiring digital ID checks before buying VPNs would increase cybercrime risks and expose IP addresses to predators.
https://www.express.co.uk/news/uk/2217934/vpn-ban-table-july-labour
#vpn #socialmediaban #ageverification #ukpolitics #cybersecurity #onlinesafety #ukpol #vpns #ProtectVPNs #privacy #onlinesafetyact
This dumb password rule is from ANZ Bank.
Your password needs to be between 8 and 16 characters long - no special characters allowed.
https://dumbpasswordrules.com/sites/anz-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Daybreak Games.
Max password length is 15 characters
The only special characters that can be used are !"#$%
https://dumbpasswordrules.com/sites/daybreak-games/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Credit Agricole.
* Login is a predefined 11 digits long identifier that you can not change
* Password is a 6 digits long identifier that you need to input using your mouse
https://dumbpasswordrules.com/sites/credit-agricole/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
NEW by me:
One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.
Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.
Data leaks followed.
#NovoNordisk #FulcrumSec #TheUSERS007 #hackandleak #extortion #AI #databreach #infosec #cybersecurity
@campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
Well that's pretty sneaky. Cybercriminals deployed ransomware on a target's network and disguised their footsteps as MS Teams traffic.
#news #technews #cybersecurity #security #microsoft #crime #cybercrime #ransomware
This dumb password rule is from Parnassus Investments.
A site responsible for protecting your investments limiting you to a
four character range with a bunch of other stupid rules? Shocking.
https://dumbpasswordrules.com/sites/parnassus-investments/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps.
Mullvad is aware of this issue. It is described in this blog:
https://mullvad.net/en/help/why-wireguard
You can download Loupe here:
https://apps.apple.com/app/id6766152470
This dumb password rule is from MKB NetBankár.
It only accepts lowercase letters, uppercase letters and numbers (any
other character counts as forbidden character).
Also, if your password contains any invalid character, it will get
marked as "Identical to the former 10 passwords".
To make it more fun, during the registration, it allows to se...
https://dumbpasswordrules.com/sites/mkb-netbankar/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
This dumb password rule is from INSS (Instituto Nacional do Seguro Social).
The National Social Security Institute (INSS) is an autarchy of the Government of Brazil linked to the Ministry of Economy that receives the contributions for the maintenance of the General Social Security System, responsible for the payment of pensions, maternity pay, death pay, sickness pay, ac...
https://dumbpasswordrules.com/sites/inss-instituto-nacional-do-seguro-social/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from WellStar MyChart.
Your password must be between 8 and 20 characters.
https://dumbpasswordrules.com/sites/wellstar-mychart/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Broadcom.
- Between 8 and 50 characters
- Can't contain any substring of length 3 or more from your email address.
- At least 1 uppercase letter, lowercase letter, and digit, and special character.
- Oh right, to really mess with password managers: no more than 10 special characters and pasting into the pa...
https://dumbpasswordrules.com/sites/broadcom/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Afraid.org FreeDNS.
Password must be between 4 and 16 characters long
https://dumbpasswordrules.com/sites/afraid-org-freedns/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Arch users PSA: https://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
1600+ AUR packages have been compromised with infostealers and rootkits.
If you've recently deployed AUR packages, please check your system if you're affected, potentially reinstall and cycle your passwords if that's the case.
this doc seems to keep the full list up to date: https://md.archlinux.org/s/SxbqukK6IA
backup: https://nextcloud.dragonhive.net/s/dXNGfjYHLN656gk?dir=/&editing=false&openfile=true
This dumb password rule is from PCPartPicker.
There are no rules for passwords. Passwords can be any length (including one character)
of any complexity. No password change confirmation emails are sent.
https://dumbpasswordrules.com/sites/pcpartpicker/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Copyright.gov.
I wonder if they cooperate with NSA to enforce the password rules.
https://dumbpasswordrules.com/sites/copyright-gov/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
The Senate Judiciary Committee chairman is demanding answers from CISA about an alarming data exposure incident wherein a contractor leaked oodles of internal CISA passwords -- including multiple AWS GovCloud credentials -- in a public GitHub profile for six months until notified by Yours Truly. The letter this week from Sen. Chuck Grassley (IA) is notable because he's the most senior lawmaker to inquire about this colossal screw up so far, and he's a Republican.
https://www.grassley.senate.gov/imo/media/doc/grassley_to_cisa_-_github_exposure.pdf
Original report on the CISA data exposure:
https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
PSA regarding a change in how Secure Boot will work in Fedora soon. The change isn't urgent, but it is something you should take a look at.
If you have any questions about this, please ask in our forum. 🙏
➡️ https://fedoramagazine.org/expiration-of-microsoft-secure-boot-keys/
Forum: https://discussion.fedoraproject.org/c/ask/6
#Fedora #Linux #OpenSource #Cybersecurity #InfoSec #SecureBoot